HUSKY Health breach: 41,000 Connecticut members and what DSS confirmed
If you were named in this filing, here’s what is being claimed, and what it would mean for you.
Connecticut’s Department of Social Services confirmed that an unauthorized person reached a HUSKY provider payment account and obtained claims and payment information for about 41,000 members. Social Security numbers, bank accounts, and electronic health records were not taken. Official letters offering free identity monitoring started going out by mail on August 21, 2026.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
What’s already out there about you?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
On August 21, 2026, the Connecticut Department of Social Services said Gainwell Technologies — the company that processes HUSKY Health payments — found unauthorized access to certain payment accounts on the HUSKY provider portal. Gainwell learned of it on June 25, 2026. The state says the outsider first got into a provider’s reimbursement account on June 18, 2026.
DSS says that person obtained claims and payment information for about 41,000 HUSKY members: full name; an identification number tied to the provider’s payment account or a Medicaid claim; dates of medical services; information about services received and how they were billed; amounts paid; and, where it applied, other health insurance policy and group numbers. Electronic health records, Social Security numbers, and financial account information were not taken. Letters to affected people started going out by postal mail on August 21, 2026, with an offer of credit and identity monitoring. DSS has not reported evidence that the information was misused. This is the second HUSKY/Gainwell provider-portal incident in 2026; a separate May notice covered about 22,500 people.
The part most coverage will undersell
Almost every account of this incident will lead with what was not taken: no Social Security numbers, no bank accounts, no electronic health records. That is true, and it is better than the alternative. It is also the least useful sentence if you are trying to decide whether this touches your life.
What the outsider actually has, according to the state, is a named list of HUSKY members plus the billing trail of their care — when services happened, what was billed, what was paid, the numbers used to process those claims, and, for some people, the policy and group numbers of their other insurance. That is not your doctor’s chart. It is the invoice of your care, with your name on it.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Someone who has that can call and mention a real visit or a real payment and sound like HUSKY, a clinic, or a billing office. They can also try to bill new services using a real claim number and a real other-insurance policy number. DSS said the activity looked financially motivated, not aimed at collecting patient files. That is not comfort. It means they took the file that is useful for billing fraud and for a call that already knows too much about you.
No public scan can tell you whether you were in this specific incident. The only official signal is the letter DSS said it began mailing on August 21, 2026.
What to actually expect
- If you were included, a letter by U.S. mail — not a surprise text, not a cold call — offering free credit and identity monitoring and fraud support. Mail can run late or go to an old address, so a delay is not proof either way.
- A second, separate paper trail if you were also in the May 2026 incident (about 22,500 people). That was a different notice about the same kind of portal. Do not assume one letter covers both.
- Calls, texts, or emails that already know you are on HUSKY, a service date, or an amount paid. Treat those as scams. The state’s own notice is a letter.
- No reset of your Social Security number or bank login. Those were not in this file. The live risk is someone using your claim or other-insurance numbers, or using the details of your care to get you to talk.
What you can and cannot fix
What left that payment account cannot be pulled back. If your name, claim or payment-account number, service dates, billed services, payment amounts, or other insurance policy and group numbers were in it, they are out. There is no recall, and no company can delete the copy the outsider already has.
- Use the official letter. Enroll in the monitoring and fraud support DSS is offering. That is the one remedy tied to this incident, and it is how you get help if someone later tries to open credit in your name.
- Read every HUSKY claim and every other-insurance explanation of benefits. Look for visits, tests, or bills you do not recognize. Medical billing fraud is the use that matches what was taken. Report unknown claims to HUSKY and to any other insurer on the letter.
- Do not confirm anything to anyone who contacts you first about this claimed breach, a “locked” HUSKY account, or a payment you need to “verify.” The state said it is writing by mail. Hang up and use a number you already have from a card or a prior official letter.
- Shrink the public listings that attach a phone, a home address, relatives, and past addresses to your name. A bare billing record is awkward on its own. It becomes dangerous when it is joined to people-search pages that tell a stranger how to reach you and who lives with you. Those listings, unlike the stolen file, can actually be removed. That is the lever you still have.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on HUSKY Health.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Oz Hair and Beauty data leak: what was taken and what to do now
In mid-August 2026 Oz Hair and Beauty confirmed that an attacker accessed its online order platform …
Oz Hair and Beauty hack: was my name, email or phone number taken?
Oz Hair and Beauty has confirmed that an unauthorised party briefly accessed its online order platfo…
Basic-Fit Gym 1 Million Members — April 2026
European gym chain Basic-Fit disclosed a breach affecting approximately 1 million members in April 2…